LWA-2026-11171 confirmed malware
functions-framework-nodejs@1.0.0
Malicious code in functions-framework-nodejs (npm)
T1059.007 · JavaScriptT1082 · System Information DiscoveryT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel
Analysis
The postinstall hook (node install.js) executes the `id` command and POSTs the captured user/group identity along with the package name, version, and timestamp to the webhook collector webhook[.]site/c3d9086b-4ce8-41d1-8526-252bb4965500. The package name impersonates the Google Cloud Functions Framework.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 11:38 AM
- analyzed
- Aug 13, 2026, 11:38 AM
Related advisories
- core-js-buffer@1.0.0
- shared-slot-gate@1.1.2
- try-lock-runner@3.2.1
- priority-mutex-lane@2.5.1
- resource-lease-pool@1.4.2
- semaphore-job-pool@2.2.2
- debug-proxy-chrome-devtools@1.0.2
- keyed-mutex-map@2.1.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.